HNHacker News
TopNewBestAskShowJobs

robotdan

49 karma · joined December 8, 2015

Hi, my name is Daniel. My voice is my passport. Verify Me.

I eat, sleep and breath FusionAuth.

[ my public key: https://keybase.io/robotdan; my proof: https://keybase.io/robotdan/sigs/bZ_z6cHOKMlganpI00p5gb2PN9IkuyCyPpXL5olj8eY ]

submissionscomments
robotdan··on Anatomy of a JWT
This is a good point. Keeping it simple is always a good engineering choice.

I think one of the reasons JWTs come up so often is that if you are going to use OAuth2/OpenID Connect - ideally the Authorization Code grant, then tokens become an important component.

And many IdPs implement the OAuth2 access token as a JWT. So it may be that your IdP ends up making this choice for you. Then you have to learn how to deal with JWTs.

robotdan··on The Difficulties of SAML Single Logout
He he... enjoy. Hopefully this doesn't trigger any nightmares. https://twitter.com/bpontarelli/status/1099067076138827776?s...
robotdan··on The Difficulties of SAML Single Logout
This thread makes me feel better with struggling to implement this. I'm not the only one.
robotdan··on Okta to Acquire Auth0 for $6.5B
To add to this... not trying to hide anything on purpose. :-) https://github.com/robotdan https://www.linkedin.com/in/robotdan/
robotdan··on Okta to Acquire Auth0 for $6.5B
Thanks for the mention. We already do see quite a few Auth0 converts. I expect to gain a lot of new customers as a result of this merger in the coming months. No complaints here.
robotdan··on Okta to Acquire Auth0 for $6.5B
>> and integrated over time > I'm reading too much into this sentence fragment and it fills me with fear.

Lol!

robotdan··on Why outsource your auth system?
> + Redhat seems quite invested in it, so it has corporate backing. This could also be a bad thing, depending on your view of Redhat and which direction they take the product.

Yes, true. :-) We'll see if IBM feels the same way.

https://www.servethehome.com/red-hat-goes-full-ibm-and-says-... http://techrights.org/2020/08/02/red-hat-layoffs/

robotdan··on Why outsource your auth system?
Nailed it.
robotdan··on Why outsource your auth system?
I think @tremon is just getting at that auth must be considered critical, and thus you should maintain some level of skill and competency to ensure you don't get blindsided.

Perhaps the distinction is just because something isn't a "core competency" does not mean it is not critical. And just because it isn't a "core competency" doesn't mean you can afford to be ignorant on the topic.

robotdan··on Why outsource your auth system?
I don't know that I'd even refer to this at outsourcing. If you can run it on premise, it is just "not building it yourself".
robotdan··on Why outsource your auth system?
Yes, this is an excellent choice as long as all of yours apps live in the Ruby world.
robotdan··on Sick of spending time on Auth, we built an open source 'Stripe for Auth'
I hope IBM/Red Hat have more sense than this, but time will tell. It may not make sense for them to maintain Keycloak with all of IBMs identity solutions.
robotdan··on Keycloak: Open-source identity and access management
FusionAuth has some k8s, helm, docker and openshift examples as well. https://github.com/FusionAuth/fusionauth-containers

FusionAuth is not open source, so if that is a hard requirement, you'll have to skip it.

robotdan··on Ask HN: What are all the things that can go wrong during authentication?
Keycloak is a good option, but if you're not a Java development it may feel a bit cumbersome to setup.

There are a bunch of good options out there - and all of them are likely better than trying to go it alone!

robotdan··on Ask HN: What are all the things that can go wrong during authentication?
Dang that is quite a list. Thanks for sharing. Makes me think twice about my current solutions.
robotdan··on OAuth Device Authorization for Roku, AppleTV, Xbox
The last time I had to type in my Netflix password into my Roku using a d-pad I nearly chucked the remote at my TV.

Not sure why everyone doesn't use this type of device authentication.

robotdan··on Show HN: Hydra – Open-Source OAuth2 Server
This may be of use, this is the Authorization Code Grant, but many others are documented as well.

https://fusionauth.io/articles/logins/webapp/oauth-authoriza...

https://fusionauth.io/articles/logins/types-of-logins-authen...

robotdan··on Show HN: Hydra – Open-Source OAuth2 Server
+1 for FusionAuth. FusionAuth has some example k8s and helm configurations available as well.

Full disclosure I work for FusionAuth. We support all of these configurations.

robotdan··on We built the FusionAuth brew Formula (with 50% more code)
Nice writeup. Brew is fantastic on macOS, do you have something similar on Windows?
robotdan··on Reactive Hashing Explained
I'd like to see some of these ideas get off the ground.

Ben mentions his email and Twitter handle in the post if anyone is interested in helping or contributing in some fashion to an open source library to implement some form of this strategy.

robotdan··on Got users? How about 100M of them?
Like Got Milk? I see what you did there. :-)
robotdan··on Save a CPU – Ditch BCrypt, Use SHA2 Instead
Why? I have yet to find concrete reasons how this makes a hash more vulnerable.

Lots of people like to dismiss it, but without any reason. Seems weak.

robotdan··on Save a CPU – Ditch BCrypt, Use SHA2 Instead
Do you know of anyone that has used this strategy in production?
robotdan··on Making Node.js Auth Suck Less
How much less suck are we talking about? Kind of sucks in most languages.
robotdan··on DevTools: FusionAuth installs on any box with or without containers
I'd like to find anyone using Keycloak and see what they like most about it, and what we could offer in FusionAuth to make it compelling to consider switching - if IBM buying Red Hat wasn't enough of a reason. :-)
robotdan··on Revoking JWTs (JSON Web Tokens)
The core is not open source, written in Java.
robotdan··on Revoking JWTs (JSON Web Tokens)
I'd say it is always good to have options. If sessions work, that is a safe option and easy to manage state.

If at scale this option doesn't work - or at least not as well as you'd like, additional strategies are good to know.

If you plan for Pokemon Go, or Fornite scale, decoupling may be beneficial. Admittedly this is a small percentage of all of the use cases.

robotdan··on Revoking JWTs (JSON Web Tokens)
Adding a transaction around the webhook could help with this. At least you'd know for sure everyone has agreed upon the state of the user.

But agreed, webooks in general are not excellent for critical events in general unless there are additional ways and of confirming receipt and confirmation.

robotdan··on Revoking JWTs (JSON Web Tokens)
Many prevailing strategies simply persist the JWT, this works, but is more difficult to scale and sort breaks the portability idea in my opinion.

Once you persist it - you might as well be using a session. I suppose it depends on your scale - maybe with just a couple of thousand users it would work ok to store every JWT issued for their lifespan.

robotdan··on Developers guide to GDPR
Seems like all GPDR did was force you to accept a cookie when you use a website - instead of actually making websites be less sucky.
Page 1 of 3Next →